How secure is Swish-e?
We know of no security issues with using Swish-e. Careful attention has been made with regard to common security problems such as buffer overruns when programming Swish-e. The most likely security issue with Swish-e is when it is run via a poorly written CGI interface. This is not limited to CGI scripts written in Perl, as it’s just as easy to write an insecure CGI script in C, Java, PHP, or Python. A good source of information is included with the Perl distribution. Type perldoc perlsec at your local prompt for more information. Another must-read document is located at http://www.w3.org/Security/faq/wwwsf4.html. Note that there are many free yet insecure and poorly written CGI scripts available — even some designed for use with Swish-e. Please carefully review any CGI script you use. Free is not such a good price when you get your server hacked…